The dependency surface is large for an early-stage framework, and the version remains below 1.0. The repository could not be found, making maintenance and provenance difficult to verify; this old release is a risky dependency choice.
38%
Total Score
50
50
The package has had no release in over six years, with zero releases in the last 12 months. That long gap strongly raises abandonment and compatibility risk.
The package declares 23 runtime dependencies, creating a broad dependency and compatibility surface for a small, early-stage framework. No provided signal shows that this complexity is actively maintained or otherwise compensated.
The latest release is still below 1.0, indicating an immature API and a higher chance of breaking changes or incomplete maintenance. Its non-prerelease status provides only limited reassurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
psr/cache Version ^1.0 | — | — |
jbzoo/utils Version ^2.3 | — | — |
ramsey/uuid Version ^3.8 | — | — |
azonmedia/di Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.